Severity
5.4MEDIUMNVD
OSV7.8OSV3.5
EPSS
0.1%
top 66.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 24

Description

An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:NExploitability: 1.2 | Impact: 4.2

Affected Packages5 packages

NVDlinux/linux_kernel4.44.4.271+6
Debianlinux/linux_kernel< 5.10.46-1+3
Ubuntulinux/linux_kernel< 4.15.0-151.157+3
debiandebian/linux< linux 5.10.46-1 (bookworm)

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

10
GHSA
GHSA-f393-4p85-6h6g: An issue was discovered in the Linux kernel 52022-05-24
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-03-22
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2022-02-22
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2021-07-20
OSV
linux-kvm vulnerabilities2021-06-25

📋Vendor Advisories

17
CISA ICS
Siemens SCALANCE FragAttacks2022-04-14
Ubuntu
Linux kernel vulnerabilities2022-03-22
BSD
FreeBSD-SA-22:02.wifi: Multiple WiFi issues2022-03-15
Ubuntu
Linux kernel vulnerabilities2022-02-22
Android
CVE-2020-26147: Closed-source component2021-10-01

💬Community

1
HackerOne
Fragmentation and Aggregation Flaws in Wi-Fi2021-07-23
CVE-2020-26147 — Linux Kernel vulnerability | cvebase